Last week we gave a talk at the very first 31c0n in
Auckland, New Zealand. The talk focused mainly on the methodology that we use to
assess security products.
More specifically, this methodology consists of 7 steps
Literature Research
Jailbreak the Target
Identify Components
Understand the Architecture
Map the Attack Surface
Prioritize
Analyze.
Details on these steps as well as general suggestions to viable alternatives for
security products can be found
here in the
slides.
The event of the events is getting closer and again, we are very optimistic to
have a lot of awesome
trainings, talks, evening events, and discussions.
But we again will also have some “features” and gimmicks for those of you who
would like to play with new, old, or just interesting technologies. As you might
remember, since some years one of these features is and again will be our own
GSM Network. As we are
improving our setup from
year to year, this time we’d like to give you the chance to actively participate
with ideas and your own services.
“Lockpicking in the IoT, …or why adding BTLE to a device sometimes isn’t smart
at all” by Ray was one of my favourite talks, as it beautifully showed many
different attack vectors as well as giving a nice guide for getting started in
this area.
It impressed me how carefree vendors and startups handled hardware and software
security in “smart” devices as it seems that their devices were more or less
easy to own. In his talk Ray pointed out physical AND implementational
weaknesses that remained even after he reported them to the vendors.
The most prominent sample he gave was when he opened a “Masterlock” by spinning
a magnet on the lock itself to open it.
This
was one of the few technical talks at 33c3 I managed to see, by that I mean
live-stream during an access control shift, by Clémentine Maurice and Moritz
Lipp.
The talk gave an overview of some already known possible information leaks by
abusing certain x86 instructions(the same concept applies to ARM too though) and
demonstrating the various ways an attacker could use them. They started off by
quickly explaining how the caches on modern CPUs are set up and how they work
and how you can exploit the timing differences in memory accesses to leak data
without actually knowing the content of the cache. This data leak can then be
used to establish a covert channel.
This is part 1 of our report series on interesting talks of the 33rd
Congress of the Chaos Computer Club. Every year the congress attracts hundreds
(up to twelve thousand this year) of technical interested people with the
opportunity to socialize and exchange knowledge with each other. The congress is
organized by the European largest hacker association and speakers give talks
about technical and societal issues like surveillance, privacy, freedom of
information, data security and various more.
Hi there,
Like in recent years the popular
Hacking 101 workshop
will take place on TROOPERS17, too! The workshop will give attendees an insight
into the hacking techniques required for penetration testing. These
techniques will cover various topics:
information gathering
network scanning
web application hacking
low-level exploitation
…and more!
During this workshop you will learn, step by step, a testing methodology
that is applicable to the majority of scenarios. So imagine you have to
assess the security of a system running on the Internet. How would you
start? First, you need a good understanding about the target, including running
services or related systems. Just scanning an IP will most likely not reveal
a lot of information about the system. The gathered information may help you to
identify communication relations of services that could include vulnerabilities.
A brief understanding of the target and it’s related
systems/services/applications will make scanning and identifying
vulnerabilities a lot easier and more effective. Then, the last step will be
the exploitation of the identified vulnerabilities, with the ultimate aim to
get access to the target system and pivot to other, probably internal,
systems and resources.
I am looking forward to our newly introduced dedicated Forensic Computing
Training at TR17!
We will start the first day with a detailed background briefing about Forensic
Computing as a Forensic Science, Digital Evidence, and the Chain of Custody. The
rest of the workshop we will follow the Order of Volatility starting with the
analysis of persistent storage using file system internals and carving, as well
as RAID reassembly with lots of hands-on case studies using open source tools.
As a next step, we will smell the smoking gun in live forensics exercises.
Depending on your preferences we will then dig a bit into memory forensics and
network forensics.
There are only two and a half months left, so I’d like to publish the next two
talks for TelcoSecDay 2017,
taking place at 21st of March in Heidelberg. Both talks are about the security
of an upcoming technology which importance will raise in near future: 5G
Networks.
One of the talks will be from an attacker’s point of view, highlighting
weaknesses of 2G/3G/4G networks and what we have to fix in 5G, and the other one
will give us insights into current developments of the 3GPP standardization
group.
The
1-day training from last TROOPERS
has become a 2-day training, featuring even more real-world attacks and defenses
as well as new hands-on sessions! We’ll teach you, step by step, how to spot and
exploit crypto vulnerabilities, how to use the strongest forms of
state-of-the-art cryptography to secure modern systems (like IoT or mobile
applications), and bring you up to speed on the latest and greatest developments
in the world of cryptography, such as TLS 1.3, blockchains, and post-quantum
crypto.
We had to make some tough choices regarding our TROOPERS17
Main Conference Agenda. Thank you again to everyone for submitting! The full
agenda will be published later this week, but for now here are the next round of
talks!
Ivan Pepelnjak: Securing Network Automation
If you have operational experience in running large networks then you’re
probably yearning to replace the traditional way of managing individual network
devices via SSH with something better and more reliable. Software Defined
Networking (SDN) was touted as the all-encompassing solution, but what we got
instead is a heap of academic ideas, several platforms that require as much
investment as an SAP deployment, and a bunch of proprietary products focused
more on increasing lock-in and vendor revenue than solving operational problems.